Zend2 VPN
Zend2 VPN Privacy Policy
Version 2026-09-09
Effective: 9 September 2026. Last updated: 15 September 2026.
Canonical URL: https://zend2.com/legal/vpn/privacy/2026-09-09
This policy describes how Zend2 handles information when you use Zend2 VPN. It is written from current product and backend behavior. It is not a claim of zero data collection, anonymity, or “no logs.” Zend2 Private Browser has a separate privacy policy at https://zend2.com/legal/privacy/2026-08-08.
1. Introduction
Zend2 VPN is an Android VPN that uses Android VpnService and WireGuard. Borsa is Zend2’s account and control plane. Google Sign-In is used for authentication. This policy covers Zend2 VPN product registration, VPN sessions, and related account data. It does not make the zend2.com VPN Finder comparison tool part of Zend2 VPN.
2. Services covered
- The Zend2 VPN Android app
- Borsa APIs used to register a VPN product account, list VPN locations, provision a session, and disconnect
- Zend2 Plus, when the same Zend2 account has Plus after Google Play verification
3. Account data (Google Sign-In)
Zend2 verifies a Google ID token and does not store that ID token after verification.
The Zend2 account record can include:
- Google subject identifier
- Email, display name, and profile photo URL provided by Google
- Account status and last login time
- A Zend2 VPN product-account record (registration time, product status, last VPN login)
- Which VPN Terms and Privacy versions you accepted, with time, app version, and platform
- Session tokens (stored as hashes, not as reusable plaintext after issue)
One Google identity is one Zend2 account. VPN legal acceptance is stored on the VPN product account. Browser legal acceptance is separate and is described in the Browser privacy policy.
4. Device data
If the app registers a device, Borsa can store an install identifier, platform, app version, optional push token if the app sends one, and a link to the VPN product account. VPN sessions are tied to that account and device.
5. VPN session / control-plane data
To provision and operate a VPN session, Borsa records control-plane metadata. Based on current backend design, that can include:
- Account and device identifiers
- Selected or assigned country / location identifier
- WireGuard public key (and a fingerprint of it)
- Assigned VPN client address (tunnel address allocated for the session, such as an address in the VPN network)
- The public IP address observed by our backend when a new VPN session row is created. Repeating an equivalent grant that reuses the same session does not overwrite or add a new source-IP record
- VPN Edge used for the session (host/port and related Edge configuration identifiers)
- Session status and timestamps (created, provisioned, disconnect requested/completed, and similar operational times)
- Failure codes when provisioning or disconnect does not succeed
- Bandwidth / usage accounting already collected for the VPN product (byte totals and related operational timestamps, not destinations)
We use this session information for service operation, security, abuse and fraud prevention, enforcement of our terms, and responding to valid legal requests where required or permitted.
These VPN session records are not browsing-history records. This source-IP capture does not record URLs, search queries, webpage contents, page titles, DNS query history, HTTP or packet contents, browsing history, or destination IP addresses or destination ports. The public source IP is distinct from the WireGuard tunnel client address.
Borsa does not receive or store:
- Your WireGuard private key (it remains on the device)
- Edge WireGuard private keys
- Destination IP addresses, URLs, domains, or search queries
- DNS query names or packet payloads
- Browsing history or the content of your communications
Zend2 does not claim that VPN Edge, hosting providers, or third-party DNS resolvers see nothing. Those systems necessarily handle network data required to deliver a tunnel. This policy does not claim traffic or content inspection by Zend2, and it does not claim a “no logs” VPN.
6. How the tunnel works
The app sends the public key to Borsa. Borsa checks entitlement and legal acceptance, allocates a client address, and asks the selected VPN Edge to install that public key as a peer. Traffic then flows over WireGuard between the device and that Edge. Default tunnel routing for IPv4 is a full-tunnel configuration (0.0.0.0/0) when the VPN is up. This policy does not claim IPv6 leak protection or that every app on the device is always captured.
7. DNS
A VPN Edge may be configured with DNS server addresses that the app applies for the tunnel. Current Borsa defaults are 1.1.1.1 and 1.0.0.1 (Cloudflare public DNS) unless a specific Edge is configured otherwise. Those resolvers are third parties and have their own policies. Zend2 does not store your DNS queries in Borsa.
8. Subscription and Google Play data
If you buy Zend2 Plus, Google Play processes payment. Free and Plus entitlements are controlled by Borsa on the Zend2 account, not as a separate “VPN Plus” product. Zend2 stores subscription/entitlement state needed to know whether Plus is active (for example plan, status, product identifiers, expiry, and a purchase token used for Google verification). Zend2 does not collect card numbers through the website or app. Google’s privacy policy applies to Play billing.
9. Operational / security diagnostics
Zend2 uses operational error monitoring (GlitchTip, Sentry-compatible) with default PII sending disabled and additional sanitizing. Unexpected errors can still include technical diagnostics. Web server and application logs may include IP addresses and API paths (for example /api/v1/vpn/grant), not VPN destinations. Rate limits, session caps, and account status are used to reduce abuse. Zend2 may apply additional abuse or security controls at VPN egress. That is not a claim that Zend2 inspects communication content.
10. Data Zend2 does not collect in Borsa
- WireGuard private keys
- Browsing history, visited URLs, or page content
- DNS query logs in the account/control plane
- Payment card numbers
11. Data retention
Contact emails are kept as needed to respond and for ordinary business records.
While a Zend2 VPN account is active, VPN control-plane rows (product account, VPN legal acceptances, VPN sessions including any public source IP recorded at session creation, and IP leases) are stored so Zend2 can operate, debug, and protect the service. Product code does not enforce a fixed retention clock for those rows while the account exists.
Hosting access-log retention should be confirmed by the operator. GlitchTip/Sentry and Apache logs are not purged by Zend2 account deletion.
12. Account deletion
Deleting a Zend2 account is identity-wide: it affects Zend2 VPN and Zend2 Private Browser for that Google identity. Current deletion behavior anonymizes identity fields, removes API tokens, cancels active/grace Plus entitlement on the account, deletes registered devices, and removes VPN session rows (including any public source IP recorded when those sessions were created) together with related VPN leases. It does not cancel Google Play billing. Legal-acceptance records may remain. Zend2 Private Browser private-connection records, including public source IP at grant time, may remain after the same deletion; that is described in the Zend2 Private Browser Privacy Policy. Account deletion does not purge GlitchTip/Sentry or Apache logs. See zend2.com/account-deletion. You can also email hello@zend2.com.
13. Security
Zend2 uses transport encryption for the website and API, hashed API tokens, and server-side checks for Plus and VPN provisioning. WireGuard encrypts tunnel traffic between the device and the VPN Edge. No method of transmission or storage is perfectly secure.
14. Children’s privacy
Zend2 VPN is not directed to children under 13. Zend2 does not knowingly collect information from children under 13. If you believe a child has created an account, contact hello@zend2.com.
15. International processing
Zend2 may process account and control-plane data on servers in more than one country. VPN Edges may be in the country you select or in the Automatic country Zend2 assigns. A specific legal entity, postal address, and hosting-region list are not stated here because they are not confirmed in the public site repository. If you need this for a legal request, email hello@zend2.com.
16. Changes
We may update this policy. The version string and canonical URL identify the current VPN Privacy Policy. The Android app may require acknowledgement of a new privacy version before you continue.
17. Contact
Questions: hello@zend2.com or the Contact page. Related: Zend2 VPN Terms of Service. Account deletion: Delete your Zend2 account.